5 ms·
I'd assume most of the people posting this happily instal random packages from npm without second thought. Surely it can be a potential threat but in most case
by zn44 6y ago
I'd assume most of the people posting this happily instal random packages from npm without second thought.
Surely it can be a potential threat but in most case there is a VERY long list of things you need to secure before it's reasonable to worry about your IDE
- gjvc 6y agoI agree with you on both counts. One of my first jobs was wearing a build engineer hat building software in a completely clean-room environment (no network, nothing), using completely vanilla installations of operating systems and compilers. A few years later, when I moved to Java, I was shocked to see people download .jar files from the central Maven repository without a care in the world, use them in development and do the same process for production. A few years after that, npm came along and made it normal for Javascript. By this time there appeared to be no stopping the madness, and incidents like this https://www.theregister.com/2016/03/23/npm_left_pad_chaos/ https://www.theregister.com/2016/03/23/npm_left_pad_chaos/ seemingly failed to give people pause. CI/CD as practised today contains huge risks on what is ingested to a given corporate infrastructure -- millions of lines of code from external sources of differing security levels. But instead of all that in plain sight, a single inaccurate article based on speculation can get people worried about something else. (related, but as you say, a very long way off from the most targets potentially most vulnerable and valuable-to-an-attacker). Crazy.
- burntoutfire 6y agoI'm guessing companies assume that whatever code gets written in-house will have more vulns that some widely used open source project... Not to mention the cost to re-implement the world (sans the OS and compiler) would be astronomical and put most projects into the "not worth it" category.
- gjvc 6y agoI'm not talking about not-reinventing-the-wheel, I'm talking about making network calls by default, to fetch dependencies. This makes review of such things seem obstructive. As ever, convenience and security are opposing forces.